CFADVISORY-CL-application-security-waf-waf-release-2025-05-27
WAF - WAF Release - 2025-05-27
CVEs:CVE-2024-48248CVE-2025-1098CVE-2025-30066CVE-2025-31324CVE-2025-31644CVE-2025-32421CVE-2025-32432CVE-2025-4427CVE-2025-4428
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.
WAF - WAF Release - 2025-05-27
CVEs:CVE-2024-48248CVE-2025-1098CVE-2025-30066CVE-2025-31324CVE-2025-31644CVE-2025-32421CVE-2025-32432CVE-2025-4427CVE-2025-4428
Resolving a request smuggling vulnerability in Pingora
CVEs:CVE-2025-4366
WAF - WAF Release - 2025-05-19
CVEs:CVE-2024-38475CVE-2024-56145CVE-2025-27520CVE-2025-34028
Vulnerability transparency: strengthening security through responsible disclosure
WAF - WAF Release - 2025-05-05
CVEs:CVE-2021-20040CVE-2021-20041CVE-2021-20042CVE-2024-52875CVE-2025-24893CVE-2025-31489CVE-2025-3248
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.